Saturday, 10 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Meta ads steered Polish Android users into a premium-rate billing trap

The Register ·
Meta ads steered Polish Android users into a premium-rate billing trap

Poland's Computer Emergency Response Team (CERT Polska) has disrupted an Android toll fraud campaign that used paid Meta ads to steer Polish users toward malicious apps on Google Play.

Its investigation documented 1,235 Meta ads, 852 of which promoted 17 apps tied to the operation.

Six contained confirmed toll fraud components or direct links to them; the other 11 shared malicious loaders, although researchers could not recover their final payloads.

Toll fraud uses malware to enroll mobile subscribers in paid services without their informed consent.

Depending on the provider, the malware may send a premium-rate SMS or automate a carrier billing flow, including intercepting the verification code needed to approve a subscription.

The charges then appear on the victim's phone bill or are deducted from their prepaid balance.

In one observed route, the malware sent generated keywords to premium-rate SMS short codes – abbreviated numbers used for paid services – to request or confirm a purchase.

CERT checked three such numbers against the Polish telecom regulator UKE's public register and found that all were active premium services.

The campaign supported two billing routes.

The three registered short codes charged 30.75 PLN ($7.97) per message, while a separate direct-carrier billing offer operated by Teleaudio advertised a recurring charge of 17 PLN ($4.41) every seven days.

Kacper Ratajczak, senior security engineer at CERT Polska, did not disclose how many people were affected or their total losses.

The three short codes were registered for use across Poland's four major mobile operators: Orange, T-Mobile, Play, and Polkomtel.

The investigation began with two Facebook ads falsely warning Polish users that their PDF application had expired.

Clicking either ad opened the Google Play listing for Messenger Pro, an unrelated SMS app containing the malicious loader.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›